# UAT-11795

> As of 2026-07-18, UAT-11795 is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 3 threats spanning malware. ATT&CK coverage spans 68 techniques across 12 tactics in 3 of 3 tracked threats. Most-observed techniques: T1005 (Data from Local System), T1008 (Fallback Channels), T1027 (Obfuscated Files or Information).

- **Nation:** Russia
- **Tracked threats:** 3
- **Categories:** MALWARE
- **As of:** 2026-07-18

## ATT&CK techniques observed

68 techniques observed across 3 of 3 tracked threats. Tactics: Stealth (formerly Defense Evasion) (12), Execution (11), Discovery (10), Collection (9), Command and Control (8), Credential Access (4).

- [T1005](https://intel.threadlinqs.com/technique/T1005) Data from Local System — Collection — observed in 3 of 3 tracked threats
- [T1008](https://intel.threadlinqs.com/technique/T1008) Fallback Channels — Command and Control — observed in 3 of 3 tracked threats
- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 3 of 3 tracked threats
- [T1033](https://intel.threadlinqs.com/technique/T1033) System Owner/User Discovery — Discovery — observed in 3 of 3 tracked threats
- [T1041](https://intel.threadlinqs.com/technique/T1041) Exfiltration Over C2 Channel — Exfiltration — observed in 3 of 3 tracked threats
- [T1053.005](https://intel.threadlinqs.com/technique/T1053.005) Scheduled Task — Persistence — observed in 3 of 3 tracked threats
- [T1055](https://intel.threadlinqs.com/technique/T1055) Process Injection — Privilege Escalation — observed in 3 of 3 tracked threats
- [T1056.001](https://intel.threadlinqs.com/technique/T1056.001) Keylogging — Collection — observed in 3 of 3 tracked threats
- [T1059.001](https://intel.threadlinqs.com/technique/T1059.001) PowerShell — Execution — observed in 3 of 3 tracked threats
- [T1059.005](https://intel.threadlinqs.com/technique/T1059.005) Visual Basic — Execution — observed in 3 of 3 tracked threats
- [T1059.006](https://intel.threadlinqs.com/technique/T1059.006) Python — Execution — observed in 3 of 3 tracked threats
- [T1071.001](https://intel.threadlinqs.com/technique/T1071.001) Web Protocols — Command and Control — observed in 3 of 3 tracked threats
- [T1082](https://intel.threadlinqs.com/technique/T1082) System Information Discovery — Discovery — observed in 3 of 3 tracked threats
- [T1102.002](https://intel.threadlinqs.com/technique/T1102.002) Bidirectional Communication — Command and Control — observed in 3 of 3 tracked threats
- [T1105](https://intel.threadlinqs.com/technique/T1105) Ingress Tool Transfer — Command and Control — observed in 3 of 3 tracked threats

## Tracked threats

- [Starland RAT Campaign (UAT-11795) — Trojanized WebEx, Zoom, MobaXterm, DBeaver & FACEIT Installers Deliver Python RAT and Novel WLDR PowerShell C2 Implant](https://intel.threadlinqs.com/threat/TL-2026-1454) — HIGH
- [UAT-11795 Deploys Novel Starland RAT and Bespoke WLDR C2 Implant in Financially Motivated Campaign](https://intel.threadlinqs.com/threat/TL-2026-1413) — HIGH
- [UAT-11795 (Russian) Trojanizes WebEx, Zoom, MobaXterm, DBeaver, FaceIT Installers to Deploy Starland RAT and Bespoke WLDR C2 Implant](https://intel.threadlinqs.com/threat/TL-2026-1411) — HIGH

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/UAT-11795
